BULLETIN №082Last updated · 30 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21.2%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 06 Dec 2011 | Composad s.r.l.Composad s.r.l. was fined by the Garante €26,000 for processing personal data collected through its website without properly appointing a data processor. The case concerned a breach of data protection rules and related organizational obligations. | IT | Garante | GDPR | €26,000 | ↗ |
| 09 Feb 2011 | Futurgroup s.r.l.Futurgroup s.r.l. was fined by the Italian data protection authority, Garante, in the amount of EUR 9,000. The case concerned the failure to provide timely information to the data subject as required by the data protection code. | IT | Garante | GDPR | €9,000 | ↗ |
| 11 Apr 2019 | AD Sphera Group s.r.l.AD Sphera Group s.r.l. was fined EUR 2,400 by the Garante for failing to provide the required privacy notice on its website. The breach concerned Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 22 Jun 2016 | Istituto Maria Angelica Miliziano s.r.l.Istituto Maria Angelica Miliziano s.r.l. was fined by the Garante 2,400 EUR for collecting users’ personal data through its website without providing the required information notice. The authority found a breach of Article 13 of the Italian Data Protection Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 06 Jul 2023 | Romagna Dolciumi s.r.l.Romagna Dolciumi s.r.l. was fined by the Garante in the amount of €10,000 for failing to provide an employee with access to their personal data. The authority also found that the company engaged a private investigative agency to carry out defensive investigations without proper authorization, in breach of GDPR requirements. | IT | Garante | GDPR | €10,000 | ↗ |
| 27 Jan 2022 | Circolo culturale “Ruian”Circolo culturale “Ruian” was fined EUR 2,000 by the Garante for operating a video surveillance system in breach of data protection rules. The cameras were not properly signposted, which failed to meet the required information obligations toward monitored individuals. | IT | Garante | GDPR | €2,000 | ↗ |
| 13 Dec 2012 | Studio Immobiliare Conca D'Oro s.r.l.Studio Immobiliare Conca D'Oro s.r.l. was fined by the Garante 6,400 EUR for making promotional phone calls without providing the required information notice and without obtaining consent. The authority found this to be a breach of the Italian Data Protection Code. | IT | Garante | GDPR | €6,400 | ↗ |
| 05 Dec 2013 | Associazione culturale KoalaAssociazione culturale Koala was fined 30,000 EUR by the Italian Garante. The case concerned the installation of a fingerprint recognition system for user access without providing the required information to the supervisory authority. | IT | Garante | GDPR | €30,000 | ↗ |
| 21 Mar 2018 | Ordinanza ingiunzione - 21 marzo 2018 [9004702]The Garante imposed a EUR 92,000 fine on a medical professional for processing the personal data of 23 patients without the required consent. The authority found a breach of privacy and data protection rules. | IT | Garante | GDPR | €92,000 | ↗ |
| 14 Jan 2016 | Q.12 s.r.l.Q.12 s.r.l. was fined EUR 2,400 by the Garante for failing to provide an adequate simplified privacy notice for its video surveillance system. The authority found a breach of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 23 Jan 2008 | Cubo società consulenza aziendale s.r.l.Cubo società consulenza aziendale s.r.l. was fined by the Garante 10,000 EUR for violating data protection rules. The case concerned the processing of personal data in the context of personnel search and selection activities. | IT | Garante | GDPR | €10,000 | ↗ |
| 11 Jan 2024 | dott. BagnatoA doctor was fined by the Garante for breaching privacy rules. The case involved improper handling of medical prescriptions outside the office, which could expose sensitive personal data. | IT | Garante | GDPR | €20,000 | ↗ |
| 29 Nov 2012 | Enterprise Work s.r.l.Enterprise Work s.r.l. was fined by the Garante in the amount of 41,600 EUR. The case concerned the sending of unsolicited promotional faxes without valid recipient consent. | IT | Garante | GDPR | €41,600 | ↗ |
| 10 Jul 2025 | Istituto Comprensivo 2 C.D.The Garante fined Istituto Comprensivo 2 C.D. EUR 4,000 for breaches of data protection rules. The authority cited non-compliance with the principles of lawfulness, fairness, and transparency in the processing of personal data. | IT | Garante | GDPR | €4,000 | ↗ |
| 01 Feb 2018 | Provincia di BeneventoProvincia di Benevento was fined by the Garante for unlawfully publishing special-category personal data on its website, including health information and tax codes. The authority found a breach of data protection rules. | IT | Garante | GDPR | €60,000 | ↗ |
| 04 Apr 2007 | Asl Brindisi 1The Garante fined Asl Brindisi 1 for failing to notify the processing of personal data under the Italian Data Protection Code. Article 37 was violated, and the fine amounted to EUR 20,000. | IT | Garante | GDPR | €20,000 | ↗ |
| 05 Sept 2013 | Stefano EvangelistaStefano Evangelista was fined by the Garante 2,400 EUR for failing to provide the required privacy notice for a video surveillance system at his business, Pizzeria del Borgo. The case concerned a breach of Article 13 of the Italian Privacy Code. | IT | Garante | GDPR | €2,400 | ↗ |
| 25 Mar 2021 | Convitto Nazionale Statale "Giordano Bruno"Convitto Nazionale Statale "Giordano Bruno" was fined by the Garante for breaching data protection principles. The authority found that personal data had been made available online for an extended period, contrary to the principles of lawfulness, fairness, transparency, and data minimization. | IT | Garante | GDPR | €1,000 | ↗ |
| 24 Jun 2010 | Enterprise Group s.r.l.Enterprise Group s.r.l. was fined EUR 238,000 by the Garante. The authority found that the company failed to provide timely information to data subjects and sent unsolicited marketing communications without prior consent. | IT | Garante | GDPR | €238,000 | ↗ |
| 18 Jan 2018 | KRI S.p.A.KRI S.p.A. was fined by the Italian data protection authority, Garante, for failing to notify the cessation of certain personal data processing activities. The case involved geolocation data and profiling, and the required notification was not made under the Italian data protection code. | IT | Garante | GDPR | €180,000 | ↗ |